Built to hold sensitive deals.
How Charm protects the accounts and data you connect. Charm is in private beta — this page describes how the product works today; formal audits and certifications will follow before general availability.
The short version
- Your connection to Charm is encrypted in transit (HTTPS / TLS).
- You sign in with Google and HubSpot’s own OAuth — we never see or store your passwords.
- Charm asks for the narrowest access a feature needs, and you can revoke it anytime.
- Call capture is opt-in, per call, with consent built in.
- We keep as little as possible — your mailbox in Charm is a rebuildable cache of Gmail.
Encryption & transport
Every request between your browser and Charm travels over HTTPS (TLS). Access tokens are sent in request headers, never in URLs or query strings, so they don’t leak into server logs or browser history.
Authentication & sessions
You sign in through Google’s OAuth — Charm never sees your Google password. Sessions use short-lived signed tokens backed by refresh tokens we can revoke immediately; once revoked, a token stops working on the very next request, not whenever it would have expired.
Least privilege
Charm requests the narrowest scopes that make a feature work, and only for the sources you connect:
- HubSpot — only the specific contact properties Charm needs, never anything outside that allow-list.
- Google — the access required to sync mail and send the replies you approve.
- Each source is granted by you, one at a time, and revocable at any time.
Consent for call capture
Call capture is off until you turn it on, and it’s opt-in per call with consent prompts built in. You control how long recordings and transcripts are kept, and you can delete any of them. You’re responsible for meeting the recording-consent rules in your jurisdiction; Charm is built to help you do that, not work around it.
Data minimization
We store as little as we can. The mailbox you see in Charm is a rebuildable cache of Gmail — revoke access and it can be cleared and rebuilt from the source of truth. Message bodies are fetched only when needed, and never sent to an AI model without redaction first.
Deletion & revocation
You can disconnect Google or HubSpot from their own security settings at any time, which cuts Charm’s access immediately. Ask us to delete your account and we remove your data. How we handle data day to day is covered in the privacy overview.
Responsible disclosure
Found a security issue? We want to hear about it. Get in touch and we’ll work with you on a fix — we don’t pursue good-faith researchers who report in private and give us a chance to respond.
Charm is in private beta: this page describes how the product works today. Formal audits and certifications will come before general availability.